XSS when attaching a file to an issue

XMLWordPrintable

    • 6.01
    • 6.5

      Hi,

      I found a persistent XSS vulnerability when attaching a file to an issue.
      The steps to reproduce are the following :

      • Attach a file to an issue. Its name must contain "<script>alert('XSS')</script>". I used a python script to do that.
      • Browse to the issue and open the ALL tab under activity. A popup should appear.

      See the attachment for the result.

        1. XSS.png
          31 kB
          Yohan Joubert

              Assignee:
              Roman Tekhov (Inactive)
              Reporter:
              Yohan Joubert
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: